What Changed Once the Registry Left a Single Vendor's Hands
On December 9, 2025, Anthropic donated the Model Context Protocol (MCP) to the Linux Foundation, folding it into the newly formed Agentic AI Foundation (AAIF). Founding contributors are Anthropic, Block, and OpenAI, with Amazon, Google, Microsoft, Cloudflare, and Bloomberg joining as platinum members with governing-board seats. The legal home moved to "Model Context Protocol, a Series of LF Projects, LLC," but the maintainer ladder (Lead → Core → Maintainer → Contributor), the SEP proposal process, and the GitHub org stayed unchanged.
Scale numbers came with the announcement: over 10,000 public MCP servers now exist, monthly Python and TypeScript SDK downloads exceed 97 million, and the Claude directory alone lists 75+ connectors. At that scale, no single team can claim to have personally vetted every server it calls.
RAG and MCP Run on Different Trust Models
RAG searches a static corpus your own team collected and version-controls, so the trust boundary stays inside your data pipeline. MCP is different: it's a live supply chain where code written by outside developers gets execution and API access once it's wired into an agent. Registry metadata — status (active/deprecated), isLatest, publishedAt/updatedAt, packages — tells you who registered what and when. It does not stand in for a security review.
The protocol itself isn't static either. A spec revision candidate published in July 2026 drops the initialize handshake and the protocol-level session entirely, moving to a stateless model — existing clients built around session state have to rewrite their connection logic against newer servers. If RAG's risk is "citing a stale document," MCP's is closer to "a stranger's code holding a permission."
From Adoption to Operations: An MCP Trust-and-Version Gate Checklist
(a) Fix the planning numbers first. Block any new server from production until it clears a security and permissions review, and set that review's SLA at 3 business days. Pin the diff-detection cycle for registry status and version changes at 24 hours or less, so a change never slips by unnoticed.
(b) Four failure patterns recur. First, trusting a server because its status reads active — a repo with no commits for months can still show active for a long stretch. Second, checking a cached isLatest flag instead of the actually deployed version, so a security patch silently goes missing. Third, mistaking a similarly named server for the official one — only pinning by repository URL and commit hash, not registry name, actually prevents this. Fourth, not upgrading the client when the protocol spec changes, so handshakes start failing.
(b') Wire the recovery branches into automation. When a diff check shows a server flipped to deprecated or removed, cut off calls to it immediately and fall back to the previous pinned version or an alternate server. If handshake failures from a spec mismatch cross 1%, drop to compatibility mode without waiting for human sign-off.
(c) Scope the operations checklist by permission tier. Run new servers in a read-only sandbox for at least two weeks before granting write or execution rights. Logs must carry server name, version, repository commit hash, response latency, and failure rate as required fields, so an incident can be traced back to the exact version that broke. Don't treat the whole registry as your trust boundary — keep an internal allowlist separate from it, and block calls to anything not on that list at the gateway.
(d) Run the improvement loop weekly. Tally the changes diff alerts caught — version swaps, deprecation flips, new-server requests — by type, and feed them back into the allowlist and gate thresholds. Track the lead time from request to allowlist entry as a metric and keep shrinking it. If that number isn't moving, the review is still a manual process in disguise.
Checklist at a Glance
Now that MCP sits under a vendor-neutral foundation and servers have passed 10,000, "it's in the registry, so it's safe" no longer holds. Pin the gate to numbers — a 3-day security-review SLA, a 24-hour diff cycle, a 1% handshake-failure threshold — pair it with commit-hash pinning and a separately maintained allowlist, and your team's trust boundary holds regardless of how fast the registry keeps growing.
References
Donating the Model Context Protocol and establishing the Agentic AI Foundation — Anthropic
Announcements — Model Context Protocol (official blog)
Ask AI about this article
The assistant has read this article. Ask anything — it answers from the text and says so when something isn't in it.
Loading the chat…